Isn’t this a way to mitigate 0-day vulnerabilities? Enable auto-update for your browser? #cyberhaven #phishing #google #googlechrome
OneLogin had a similar incident a few months ago where an inadvertent Chrome browser extension update took out their entire SSO service for almost two days. At one point they had “all OneLogin engineers working on it”
Seems insane that both attack vectors were related to something most people don’t even use or care about: browser extensions. If you haven’t already, do an audit/cleanup of your browser extensions 😅
Something I learned a while ago was most (if not all) technology service interruptions are either one of two things (or both): a failed process, or human error. Seems like this (and the OneLogin outage) were the latter 😑 🤦♂️